_______________________________________________________________________
Package : php4-eaccelerator
Date : August 1, 2009
Affected: Corporate 4.0
_______________________________________________________________________
Problem Description:
A vulnerability has been found and corrected in php4-eaccelerator:
encoder.php in eAccelerator allows remote attackers to execute
arbitrary code by copying a local executable file to a location under
the web root via the -o option, and then making a direct request to
this file, related to upload of image files (CVE-2009-2353).
Additionally to adressing the security issue this update also provides
php4-eaccelerator 0.9.5.
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-2353
_______________________________________________________________________